A long release history, current stable version, organization backing, tests, and security policy provide solid support. Recent repository activity is quiet and every analyzed workflow reference is unpinned, so maintenance and build-integrity risks remain.
67%
Total Score
67
100
83
There were zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent repository push and January 2026 release provide some compensating evidence.
The repository has 25 open issues and three open pull requests, with no issues or pull requests created or closed in the last month. The lack of recent triage reinforces the maintenance concern.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, leaving build inputs exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
twig/twig Version ^3.0 | — | — |
symfony/yaml Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/string Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.